Threat Advisory

High-Severity Vulnerabilities Exploitable in Palo Alto Networks Firewalls

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Palo Alto Networks has identified several vulnerabilities across its PAN-OS software and hardware firewall platforms that could allow attackers to disrupt services or compromise network security.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Palo Alto Networks has identified several vulnerabilities across its PAN-OS software and hardware firewall platforms that could allow attackers to disrupt services or compromise network security.[emaillocker id="1283"]

CVE-2024-3385 is a high-severity vulnerability that enables denial-of-service attacks by allowing an unauthenticated, remote attacker to cause hardware-based firewalls to reboot using specially crafted packets. This can lead to the firewall entering maintenance mode, requiring manual intervention to bring it back online. This issue only impacts PA-5400 and PA-7000 firewalls when GTP security is disabled.

CVE-2024-3384 is another high-severity vulnerability that allows a remote, unauthenticated attacker to exploit PAN-OS firewalls by using specially crafted NTLM packets. This can cause a firewall to reboot and potentially enter maintenance mode, requiring manual intervention to restore the system.

CVE-2024-3382 is a high-severity vulnerability that allows an attacker to send bursts of malicious packets through the firewall, preventing it from processing traffic. This issue only affects devices with the SSL Forward Proxy feature enabled.

CVE-2024-3383 is a high-severity vulnerability related to how data received from Cloud Identity Engine (CIE) agents is processed. This flaw can be exploited to modify User-ID groups, impacting user access to network resources based on existing Security Policy rules.

Palo Alto Networks has also addressed medium-severity issues involving decryption exclusions, user impersonation, and third-party open-source components. Additionally, a medium-severity vulnerability in Palo Alto Networks' Panorama Software could allow Man-in-the-Middle (MitM) attacks and capture encrypted traffic. Palo Alto Networks recommends customers update their systems to the latest patches and follow best practices to mitigate the risk of exploitation.

RECOMMENDATION:

  • We strongly recommend you update the PAN-OS software to version 11.1 or later.

REFERENCES:

The following reports contain further technical details:
https://www.securityweek.com/palo-alto-networks-patches-vulnerabilities-allowing-firewall-disruption/

[/emaillocker]
crossmenu